Falhas do tipo CWE-73

668 resultados

Controle de acesso inadequado

A aplicação falha em validar ou enforçar corretamente quem pode acessar quais recursos ou funcionalidades. Isso permite que usuários não autorizados executem ações, visualizem dados sensíveis ou acessem áreas administrativas que deveriam estar restritas.

Exemplo

Um sistema bancário que valida se o usuário está logado, mas não verifica se ele tem permissão para acessar a conta de outro cliente — bastaria mudar o ID na URL (ex: `/conta/123` para `/conta/456`) para ver dados alheios.

Como mitigar

Implemente verificações de autorização em todas as operações sensíveis, não confie apenas em obscuridade de URLs ou IDs. Use listas de controle de acesso (ACL) ou papéis (RBAC) centralizados, e valide permissões no servidor antes de retornar qualquer dado ou executar ação.

CVE-2022-34765MEDIUMA CWE-73: External Control of File Name or Path vulnerability exists that could cause loading of unauthorized firmware images when user-contEPSS 0.6%CVE-2024-5823MEDIUMFile Overwrite Vulnerability in gaizhenbiao/chuanhuchatgptEPSS 0.5%CVE-2025-12529HIGHCost Calculator Builder <= 3.6.3 - Unauthenticated Arbitrary File DeletionEPSS 0.5%CVE-2024-8616HIGHArbitrary File Overwrite in h2oai/h2o-3EPSS 0.5%CVE-2025-0452HIGHArbitrary File Deletion in eosphoros-ai/DB-GPTEPSS 0.5%CVE-2023-0008MEDIUMPAN-OS: Local File Disclosure Vulnerability in the PAN-OS Web InterfaceEPSS 0.5%CVE-2025-54945CRITICALSUNNET Corporate Training Management System - External Control of File Name or PathEPSS 0.5%CVE-2025-9529MEDIUMCampcodes Payroll Management System index.php include file inclusionEPSS 0.5%CVE-2026-72841CRITICALluci-app-openvpn Path Traversal RCE via instance_name2EPSS 0.5%CVE-2024-43658HIGHUsing the <redacted> action or <redacted>.sh script, arbitrary files and directories can be deleted using directory traversal.EPSS 0.5%CVE-2026-66302CRITICALSkype for Business Remote Code Execution VulnerabilityEPSS 0.5%CVE-2026-54582MEDIUMmport package installation can overwrite existing unmanaged or differently owned filesEPSS 0.5%CVE-2026-15724HIGHPath traversal in Progress ShareFile Storage Zones Controller (SZC)EPSS 0.5%CVE-2026-49441CRITICALWazuh : peer-controlled metadata key in process_files_from_worker non-merged branch allows arbitrary file write under WAZUH_PATH on Wazuh managerEPSS 0.5%CVE-2024-9575HIGHLocal File Inclusion in pretix-widget WordPress pluginEPSS 0.5%CVE-2026-16137HIGHPath traversal via unsanitized upload filename leads to arbitrary file write in Progress ShareFile Storage Zones ControllerEPSS 0.5%CVE-2026-54583HIGHmport package bundle downloads allow unsafe destination filenamesEPSS 0.5%CVE-2023-5816MEDIUMCode Explorer <= 1.4.5 - Authenticated (Admin+) External File ReadingEPSS 0.5%CVE-2026-39006CRITICALAn issue in SNMP4J-Agent 3.8.3 allows a remote attacker to execute arbitrary code via the snmp4jCfgStoragePath component.EPSS 0.5%CVE-2026-34783HIGHFerret has a Path Traversal in IO::FS::WRITE allows arbitrary file write when scraping malicious websitesEPSS 0.5%